What Is the OAIC and What Enforcement Powers Does It Have Over Australian Businesses?
The Office of the Australian Information Commissioner (OAIC) is the independent federal regulator responsible for enforcing the Privacy Act 1988 (Cth). It can investigate businesses, issue binding determinations, and seek civil penalties of up to $50 million in the Federal Court. In January 2026 the OAIC commenced a proactive enforcement sweep targeting approximately 60 entities across 6 industry sectors — without waiting for complaints.
| Full name | Office of the Australian Information Commissioner |
| Established | 2010 (Australian Information Commissioner Act 2010) |
| Privacy law enforced | Privacy Act 1988 (Cth) |
| Complaint form | oaic.gov.au — online complaint form |
| Penalty — serious | Up to $50M, or 3× benefit, or 30% adjusted turnover |
| Penalty — non-serious | Up to $66,000 per contravention |
| January 2026 sweep | ~60 entities across 6 sectors, proactive (not complaint-driven) |
What does the OAIC do?
The OAIC has four main functions relevant to Australian businesses:
- Handles privacy complaints — any individual who believes their privacy has been interfered with can lodge a complaint at oaic.gov.au. The OAIC notifies the business, attempts conciliation, and investigates if conciliation fails.
- Conducts investigations — the OAIC can investigate on its own initiative under s 40 of the Privacy Act, without needing a complaint. It can require documents, compel answers, and summon individuals.
- Issues determinations — after a formal investigation, the OAIC can make binding determinations finding interference occurred and ordering remedies: an apology, compensation to the affected individual, and changes to business practices.
- Seeks civil penalties — for serious or repeated interference, the OAIC can apply to the Federal Court for civil penalty orders against the business and, in some cases, the individuals involved.
Serious vs non-serious breaches — what's the difference?
The Privacy and Other Legislation Amendment Act 2024 introduced a tiered penalty framework.
Serious interference includes: a single act or omission causing serious harm to one or more individuals; a practice showing serious disregard for the APPs; or intentional or reckless conduct. Penalties can reach the greater of $50 million, 3 times the benefit obtained, or 30% of adjusted annual turnover for the breach period.
Non-serious interference — a single, lower-severity contravention — carries up to $66,000 per contravention for corporations. Individuals, including sole traders and officers who were knowingly involved, can also face personal liability.
What does the January 2026 enforcement sweep mean?
In January 2026 the OAIC commenced a proactive examination of approximately 60 entities across 6 industry sectors — not in response to complaints, but on the OAIC's own initiative. This signals a shift from reactive regulation to proactive oversight, comparable to how the ACCC, ATO, and ASIC operate.
Businesses should not assume that having received no complaint means they are not at risk of OAIC scrutiny. The January 2026 sweep demonstrates the OAIC is willing to examine entities without prior notification or a triggering event.
How does the complaints process work?
- An individual lodges a complaint at oaic.gov.au
- The OAIC notifies the business and gives it an opportunity to respond — typically within 28 days
- The OAIC attempts conciliation: a facilitated process aimed at resolving the complaint without formal proceedings
- If conciliation fails, the OAIC may investigate and issue a formal determination
- If a determination is not complied with, or if the breach is serious, the OAIC may apply to the Federal Court
Most complaints are resolved at conciliation. Practical outcomes include an apology, updated privacy policies, changed data practices, and occasionally compensation. Federal Court proceedings are reserved for serious matters.
What mitigating factors does the OAIC consider?
- Whether the breach was inadvertent or deliberate
- Whether the business cooperated with the OAIC
- Whether prompt containment and remediation steps were taken
- Whether notification was proactive
- The size and sophistication of the business
- Whether vulnerable individuals — children, elderly people, those under financial stress — were affected
Small businesses that take genuine steps toward compliance, even imperfect ones, are treated materially differently from large organisations or businesses that deliberately disregarded their obligations.
Frequently asked questions
Can the OAIC audit my business without a complaint being lodged?
Yes. The OAIC has investigative powers it can exercise on its own initiative under s 40 of the Privacy Act. The January 2026 enforcement sweep is a direct example. The OAIC can also conduct privacy assessments — structured reviews of an APP entity's practices — without any prior complaint.
If a complaint is lodged against me, how long does the process take?
Conciliation typically takes 2–6 months from notification to resolution. If the matter proceeds to formal investigation and determination, it can take 12–24 months or longer. Prompt, cooperative engagement from the outset is the most effective way to shorten the process.
Can individuals sue my business directly for a privacy breach?
From June 2025, yes. The statutory tort for serious invasions of privacy — introduced by the Privacy and Other Legislation Amendment Act 2024 — allows individuals to bring civil claims directly in court without going through the OAIC. The tort requires the invasion to be serious, the individual to have had a reasonable expectation of privacy, and the defendant's conduct to have been intentional or reckless.
Does the OAIC publish names of businesses it takes action against?
Yes. The OAIC publishes determinations, enforceable undertakings, and media releases describing enforcement outcomes. Significant breaches often receive media coverage. The reputational dimension of enforcement is frequently as significant as the financial penalty for a small business.
I've received a letter from the OAIC saying a complaint has been made. What should I do?
Respond within the timeframe specified — typically 28 days. Engage in good faith: describe what information you hold, what happened, and what you have done or intend to do. Consider legal advice if the complaint involves a significant breach or a large number of affected individuals. Most complaints at this stage are resolved through conciliation.
The free Privacy Act Business Applicability Check shows whether your business is currently regulated by the OAIC and which obligations apply from 1 July 2026.
Check my OAIC obligations →Explore more of the Privacy Act
- Does the Privacy Act Apply to My Australian Small Business?
- What Is ADM Disclosure and Does My Australian Business Need One?
- What Counts as a Notifiable Data Breach in Australia?
- What Must an Australian Privacy Policy Include Under the Privacy Act?
- APP 1: Open and Transparent Management of Personal Information
- APP 2: Anonymity and Pseudonymity